Trojan

Trojan.Win32.Agent.neyndy (file analysis)

Malware Removal

The Trojan.Win32.Agent.neyndy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.neyndy virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Harvests cookies for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Agent.neyndy?


File Info:

name: 7E7C8C1CF3D40E737CFD.mlw
path: /opt/CAPEv2/storage/binaries/0002c222baac5482801c37e69ab173d1cd2e2e1d7040dbfeaa06468587f6f33b
crc32: BD620F89
md5: 7e7c8c1cf3d40e737cfdd42f825cca0b
sha1: 21a9c25ed9ff8075903279f2e08c6ea77da4e58c
sha256: 0002c222baac5482801c37e69ab173d1cd2e2e1d7040dbfeaa06468587f6f33b
sha512: 9d897c33632a6c58e9efbbbb8cdfee12b456a04a66fb1e8a9d059e51de16acb3d57c17cfc2bdff89147cd6cd83f99f22efea4f2386f7a2079e145ce5eea27168
ssdeep: 3072:bjr87S7Gnzbo6KcWmjRrz33eAZ1b4/vZYPkMAvhCU/MNzLAAY72NGgO:AZvMG3t3b4ZYP4vwU0/ApIGR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A24F11777D0C432E87A953A09A492225A3FFBF24AB49D5F2384519F4DB22C05EB1B33
sha3_384: f8df22425019c1922ea8151a680dbddcf343251864fa2649c3dbb65be5bf86625d5899154a2c7ad2a17b81f144cb1be5
ep_bytes: e821110000e97ffeffff558bec8325a8
timestamp: 2015-05-05 13:45:31

Version Info:

0: [No Data]

Trojan.Win32.Agent.neyndy also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.tpM6
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.46719006
ClamAVWin.Malware.Zusy-9957983-0
CAT-QuickHealTrojan.MauvaiseRI.S5264730
McAfeeW32/Ctsinf.a
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPRETrojan.GenericKD.46719006
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Agent.4ab
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.cf3d40
CyrenW32/Ransom.KX.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.NCK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.neyndy
BitDefenderTrojan.GenericKD.46719006
NANO-AntivirusTrojan.Win32.TP.fwrmck
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AvastWin32:DropperX-gen [Drp]
TencentTrojan.Win32.Agent.kkd
EmsisoftTrojan.GenericKD.46719006 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader23.51365
ZillyaTrojan.Agent.Win32.1435878
TrendMicroTROJ_GEN.R002C0DEN23
McAfee-GW-EditionBehavesLike.Win32.Ctsinf.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7e7c8c1cf3d40e73
SophosW32/CTSInf-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.AXD
JiangminTrojan.Agent.cemd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLHackTool[VirTool]/Win32.Ceeinject
XcitiumVirus.Win32.Agent.VP@8ek9ga
ArcabitTrojan.Generic.D2C8E01E
ViRobotWin32.CTS.A
ZoneAlarmTrojan.Win32.Agent.neyndy
MicrosoftTrojan:Win32/Prepscram.A!MTB
GoogleDetected
AhnLab-V3Trojan/RL.Agent.R248722
BitDefenderThetaAI:Packer.55F18FFD1F
ALYacTrojan.GenericKD.46719006
MAXmalware (ai score=86)
VBA32Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEN23
RisingVirus.CTS!1.DA0D (CLASSIC)
YandexTrojan.GenAsa!VyHVTNYrcF4
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NCK
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agent.neyndy?

Trojan.Win32.Agent.neyndy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment